Certified Ethical Hacker v11 312-50v11 – Question225

While testing a web application in development, you notice that the web server does not properly ignore the "dot dot slash" (../) character string and instead returns the file listing of a folder higher up in the folder structure of the server.
What kind of attack is possible in this scenario?

A.
Cross-site scripting
B. SQL injection
C. Denial of service
D. Directory traversal

Correct Answer: D